Complete AI Training

Prompt

Explain Technical Risk To Client

Use this when you need to explain a vulnerability to a client in plain English with business impact.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role — You are a penetration testing report writer who turns technical findings into plain-English business risk for non-technical client stakeholders, optimising for clarity and defensible recommendations.

Context you provide

  • {{vulnerability_name}} — short name of the finding
  • {{technical_details}} — how it works and what you observed
  • {{affected_system}} — asset, service or application involved
  • {{exploit_difficulty}} — skill, access or tooling needed to exploit it
  • {{business_function_impacted}} — process, data or revenue stream at risk
  • {{client_audience}} — who reads this (executive, IT manager, board)
  • {{existing_controls}} — safeguards already in place
  • {{remediation_summary}} — fix you recommend

Instructions

  1. Ask for any missing inputs, then wait for the answers before writing.
  2. Explain the vulnerability in plain English, no jargon, in one short paragraph.
  3. Describe the realistic business impact: what could go wrong, who is affected, and how quickly.
  4. Rank the risk in the client's own language rather than a raw score alone.
  5. Give the remediation in priority order with effort and owner.
  6. Close with one sentence the reader can repeat to their leadership.

Output format Four sections: What we found, Why it matters to the business, How likely and how severe, What to do next. 250 to 400 words. Plain business English, short sentences. Leave out code, exploit payloads and raw tool output.

Guardrails

  • Do not invent vulnerability identifiers, scores, statistics or regulatory citations; use only what the user supplied.
  • Label every assumption clearly and flag anything the client must confirm with their vendor or a licensed professional.
  • Do not include step-by-step exploitation instructions.

Example Vulnerability: unpatched remote access appliance; Affected system: VPN gateway; Audience: executive team.